PT-2026-2487 · Unknown · Semantic Machines

Published

2026-01-13

·

Updated

2026-01-13

·

CVE-2025-66698

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Semantic machines version 5.4.8
Description An issue allows attackers to bypass authentication by sending a crafted HTTP request to various API endpoints. The attack targets authentication mechanisms within the software. The affected API endpoints are not specified in detail. The request utilizes crafted data to circumvent normal security checks.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-66698

Affected Products

Semantic Machines